SB2026100721 - Multiple vulnerabilities in Google Chrome



SB2026100721 - Multiple vulnerabilities in Google Chrome

Published: October 7, 2026

Security Bulletin ID SB2026100721
CSH Severity
High
Patch available
YES
Number of vulnerabilities 247
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 21% Medium 11% Low 68%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 247 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-106382)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Chromecast component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


2) Use-after-free (CVE-ID: CVE-2026-106197)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Browser component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


3) Use-after-free (CVE-ID: CVE-2026-106358)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Navigation component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


4) Use-after-free (CVE-ID: CVE-2026-106347)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Track component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


5) Improper Authorization (CVE-ID: CVE-2026-102322)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in SiteIsolation in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


6) Use of uninitialized resource (CVE-ID: CVE-2026-106245)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


7) Improper Authorization (CVE-ID: CVE-2026-106327)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Core in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


8) Incomplete cleanup (CVE-ID: CVE-2026-106366)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to incomplete cleanup in CustomTabs in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the system.


9) Use of uninitialized resource (CVE-ID: CVE-2026-106258)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


10) Use of uninitialized resource (CVE-ID: CVE-2026-106376)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


11) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106308)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an incorrectly resolved reference in Autofill in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and overwrite arbitrary files on the system.


12) Use of uninitialized resource (CVE-ID: CVE-2026-106215)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


13) Missing Authorization (CVE-ID: CVE-2026-106369)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Translate in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


14) Type Confusion (CVE-ID: CVE-2026-106293)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


15) Race condition (CVE-ID: CVE-2026-106377)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Fonts in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


16) Race condition (CVE-ID: CVE-2026-106412)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Core in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


17) Incomplete cleanup (CVE-ID: CVE-2026-106243)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to incomplete cleanup in Proxy Auth in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the system.


18) Information disclosure (CVE-ID: CVE-2026-106214)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information exposure in the proxy component when the component is used. A remote attacker can exploit the information leak to disclose sensitive information.


19) Improper Authorization (CVE-ID: CVE-2026-106364)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in Omnibox in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


20) Integer overflow (CVE-ID: CVE-2026-106239)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in WebGL component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


21) Race condition (CVE-ID: CVE-2026-106426)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Fonts in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


22) Use-after-free (CVE-ID: CVE-2026-106419)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the ANGLE component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


23) Input validation error (CVE-ID: CVE-2026-106396)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in Omnibox in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.


24) Missing Authorization (CVE-ID: CVE-2026-106323)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Chrome for iOS in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


25) Use of uninitialized resource (CVE-ID: CVE-2026-106231)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in Dawn in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


26) Use of uninitialized resource (CVE-ID: CVE-2026-106202)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


27) Use of uninitialized resource (CVE-ID: CVE-2026-106273)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in Video in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


28) Incomplete cleanup (CVE-ID: CVE-2026-106203)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to incomplete cleanup in Autofill in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the system.


29) Integer overflow (CVE-ID: CVE-2026-106332)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in Compositing component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


30) Use-after-free (CVE-ID: CVE-2026-106281)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Tint component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


31) Use-after-free (CVE-ID: CVE-2026-106298)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Chrome Tabs component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


32) Use-after-free (CVE-ID: CVE-2026-106193)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Parser component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


33) Race condition (CVE-ID: CVE-2026-106255)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in V8 in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and execute arbitrary code on the target system.


34) Use-after-free (CVE-ID: CVE-2026-106393)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Storage component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


35) Use-after-free (CVE-ID: CVE-2026-106227)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Core component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


36) Use of uninitialized resource (CVE-ID: CVE-2026-106379)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in Skia in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


37) Use-after-free (CVE-ID: CVE-2026-106211)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the TabStrip component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


38) Improper Authorization (CVE-ID: CVE-2026-106329)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect authorization in FileSystem in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and execute arbitrary code.


39) Use-after-free (CVE-ID: CVE-2026-106248)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Bindings component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


40) Use-after-free (CVE-ID: CVE-2026-106235)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebAudio component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


41) Use-after-free (CVE-ID: CVE-2026-106257)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the HTML component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


42) Use-after-free (CVE-ID: CVE-2026-106268)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


43) Use-after-free (CVE-ID: CVE-2026-106278)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Select component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


44) Use-after-free (CVE-ID: CVE-2026-106233)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Metrics component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


45) Use-after-free (CVE-ID: CVE-2026-106318)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Media component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


46) Use-after-free (CVE-ID: CVE-2026-106411)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Parser component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


47) Use-after-free (CVE-ID: CVE-2026-106423)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Media component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


48) State Issues (CVE-ID: CVE-2026-106346)

CWE-ID: CWE-371 - State Issues

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper state validation in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and execute arbitrary code on the system.


49) Use-after-free (CVE-ID: CVE-2026-106190)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Media component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


50) Use-after-free (CVE-ID: CVE-2026-106357)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


51) Type Confusion (CVE-ID: CVE-2026-106240)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


52) Use of uninitialized resource (CVE-ID: CVE-2026-106184)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of uninitialized resources in Media in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger uninitialized usage of resources and compromise the affected system.


53) Use-after-free (CVE-ID: CVE-2026-106383)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Media component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


54) Use-after-free (CVE-ID: CVE-2026-106349)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the V8 component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


55) Use-after-free (CVE-ID: CVE-2026-106421)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the PDF component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


56) Use-after-free (CVE-ID: CVE-2026-106204)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the PDF component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


57) Use-after-free (CVE-ID: CVE-2026-106200)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the Track component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


58) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106265)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in File in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


59) Race condition (CVE-ID: CVE-2026-106238)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Fonts in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


60) Incorrect authorization (CVE-ID: CVE-2026-106324)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in WebAppInstalls when handling web app installation operations. A remote attacker can exploit the authorization flaw to bypass authorization restrictions.


61) Incorrect calculation (CVE-ID: CVE-2026-106420)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect calculation in API in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


62) Incorrect authorization (CVE-ID: CVE-2026-106222)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Sync in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


63) Missing Authorization (CVE-ID: CVE-2026-106208)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in API in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


64) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106286)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in Omnibox in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


65) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106181)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


66) Use-after-free (CVE-ID: CVE-2026-106315)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Modularization in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


67) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106274)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


68) Missing Authorization (CVE-ID: CVE-2026-106365)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to missing authorization in the Animation component when accessing functionality requiring authorization. A remote attacker can access animation functionality without the required authorization to bypass authorization restrictions.


69) Missing Authorization (CVE-ID: CVE-2026-106267)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


70) Missing Authorization (CVE-ID: CVE-2026-106194)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in WebAppInstalls in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


71) Incorrect authorization (CVE-ID: CVE-2026-106313)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


72) Use-after-free (CVE-ID: CVE-2026-106283)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Streaming in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


73) Use-after-free (CVE-ID: CVE-2026-106291)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within GarbageCollection in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


74) Race condition (CVE-ID: CVE-2026-106300)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in CacheStorage in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


75) Incorrect authorization (CVE-ID: CVE-2026-106314)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to incorrect authorization in the Bluetooth component when authorizing Bluetooth operations. A remote attacker can bypass Bluetooth authorization checks to bypass security restrictions.


76) Use of uninitialized resource (CVE-ID: CVE-2026-106223)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in GPU in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


77) Information disclosure (CVE-ID: CVE-2026-106242)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Omnibox in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


78) Incorrect authorization (CVE-ID: CVE-2026-106241)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Search in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


79) Incorrect authorization (CVE-ID: CVE-2026-106381)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Passwords in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


80) Missing Authorization (CVE-ID: CVE-2026-106217)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Google Lens in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


81) Missing Authorization (CVE-ID: CVE-2026-106425)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in BrowserTag in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


82) Missing Authorization (CVE-ID: CVE-2026-106225)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Autofill in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


83) Missing Authorization (CVE-ID: CVE-2026-106363)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to missing authorization in FullScreen when accessing fullscreen functionality. A remote attacker can access functionality without the required authorization to bypass authorization restrictions.


84) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106266)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in Contextual Tasks in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


85) Code Injection (CVE-ID: CVE-2026-106189)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute injected code.

The vulnerability exists due to code injection in ReaderMode when using the feature. A remote attacker can inject code into ReaderMode to execute injected code.


86) Use-after-free (CVE-ID: CVE-2026-106335)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Media in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


87) Information disclosure (CVE-ID: CVE-2026-106415)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Enterprise in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


88) Missing Authorization (CVE-ID: CVE-2026-106224)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Google Lens in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


89) Input validation error (CVE-ID: CVE-2026-106185)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Viz in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


90) Incorrect authorization (CVE-ID: CVE-2026-106244)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in the Permissions component when enforcing permissions. A remote attacker can exploit incorrect authorization checks to bypass authorization restrictions.


91) Incorrect authorization (CVE-ID: CVE-2026-106407)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in GetUserMedia in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


92) Incorrect authorization (CVE-ID: CVE-2026-106389)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in USB in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


93) Incorrect authorization (CVE-ID: CVE-2026-106397)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


94) Missing Authorization (CVE-ID: CVE-2026-106196)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Navigation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


95) Input validation error (CVE-ID: CVE-2026-106414)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


96) Protection mechanism failure (CVE-ID: CVE-2026-106408)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to protection mechanism failure in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


97) Use of uninitialized resource (CVE-ID: CVE-2026-106261)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in Video in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


98) Missing Authorization (CVE-ID: CVE-2026-106406)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


99) Use of uninitialized resource (CVE-ID: CVE-2026-106290)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in GPU in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


100) Improper privilege management (CVE-ID: CVE-2026-106378)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to an unspecified privilege-elevation weakness in the Google Chrome sandbox when interacting with the sandbox. A remote attacker can exploit this weakness to escalate privileges.


101) Missing Authorization (CVE-ID: CVE-2026-106198)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in FileSystem in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


102) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106326)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


103) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-106354)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access improperly exposed resources.

The vulnerability exists due to improper resource exposure in the extensions component when accessing extension resources. A remote attacker can access exposed extension resources to access improperly exposed resources.


104) Information disclosure (CVE-ID: CVE-2026-106342)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Autofill in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


105) Information disclosure (CVE-ID: CVE-2026-106424)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Audio in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


106) Incorrect authorization (CVE-ID: CVE-2026-106253)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Extensions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


107) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106279)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in Passwords in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


108) Incorrect provision of specified functionality (CVE-ID: CVE-2026-106361)

CWE-ID: CWE-684 - Incorrect Provision of Specified Functionality

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of certain functionality in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass security restrictions.


109) Incorrect authorization (CVE-ID: CVE-2026-106402)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Extensions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


110) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-106311)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to mislead users into performing unintended actions.

The vulnerability exists due to insufficient protection against clickjacking in PermissionElement when users interact with deceptive web content. A remote attacker can manipulate user clicks through clickjacking to mislead users into performing unintended actions.


111) Incorrect authorization (CVE-ID: CVE-2026-106246)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


112) Spoofing attack (CVE-ID: CVE-2026-106302)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent permission-related user interface information.

The vulnerability exists due to improper representation of user interface information in PermissionElement when displaying permission-related interface elements. A remote attacker can exploit this interface misrepresentation to misrepresent permission-related user interface information.


113) Code Injection (CVE-ID: CVE-2026-106416)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute injected code.

The vulnerability exists due to code injection in the extensions component when using extensions. A remote attacker can inject code to execute injected code.


114) Spoofing attack (CVE-ID: CVE-2026-106182)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to mislead a user through user interface misrepresentation.

The vulnerability exists due to improper representation of user interface information in the Paint component when rendering the user interface. A remote attacker can trigger misleading user interface rendering to mislead a user.


115) Spoofing attack (CVE-ID: CVE-2026-106282)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface information.

The vulnerability exists due to user interface misrepresentation in WebOTP when displaying its user interface. A remote attacker can exploit the WebOTP interface to misrepresent user interface information.


116) Information disclosure (CVE-ID: CVE-2026-106392)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in WebAudio in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


117) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106188)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in SignIn in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


118) Use of uninitialized resource (CVE-ID: CVE-2026-106370)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in GPU in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


119) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-106356)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to induce unintended user interface actions.

The vulnerability exists due to inadequate protection against clickjacking in EVP when users interact with the interface. A remote attacker can perform clickjacking to induce unintended user interface actions.


120) Race condition (CVE-ID: CVE-2026-106405)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in CustomTabs in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


121) Open redirect (CVE-ID: CVE-2026-106322)

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to redirect users to an unintended destination.

The vulnerability exists due to an open redirect in AppManifest when handling redirects. A remote attacker can exploit the open redirect to redirect users to an unintended destination.


122) Incorrect authorization (CVE-ID: CVE-2026-106280)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in PermissionElement when performing authorization checks. A remote attacker can exploit the authorization error to bypass authorization restrictions.


123) Input validation error (CVE-ID: CVE-2026-106206)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


124) Observable discrepancy (CVE-ID: CVE-2026-106180)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable discrepency in Animation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


125) Observable discrepancy (CVE-ID: CVE-2026-106303)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable discrepency in Autofill AI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


126) Race condition (CVE-ID: CVE-2026-106201)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in V8 in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


127) Incorrect authorization (CVE-ID: CVE-2026-106333)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Input in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


128) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106228)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in Google Lens in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


129) Missing Authorization (CVE-ID: CVE-2026-106289)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in FedCM in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


130) Information disclosure (CVE-ID: CVE-2026-106277)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Animation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


131) Missing Authorization (CVE-ID: CVE-2026-106410)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass permission restrictions.

The vulnerability exists due to missing authorization in the Permissions component when enforcing access restrictions. A remote attacker can access functionality without the required authorization to bypass permission restrictions.


132) Out-of-bounds read (CVE-ID: CVE-2026-106284)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the Printing component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


133) Spoofing attack (CVE-ID: CVE-2026-106209)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent user interface information.

The vulnerability exists due to user interface misrepresentation in the mobile interface of Google Chrome when displaying interface elements. A remote attacker can exploit this interface misrepresentation to misrepresent user interface information.


134) Cross-site request forgery (CVE-ID: CVE-2026-106216)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to cross-site request forgery in the ReadingList feature when handling cross-site requests. A remote attacker can induce a browser to send a forged cross-site request to perform unauthorized actions.


135) Incorrect authorization (CVE-ID: CVE-2026-106328)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in PDF in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


136) Missing Authorization (CVE-ID: CVE-2026-106387)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


137) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-106400)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unintended user interface actions.

The vulnerability exists due to insufficient protection against clickjacking in Messages when handling user interface interactions. A remote attacker can trick a user into interacting with a misleading interface to trigger unintended user interface actions.


138) Missing Authorization (CVE-ID: CVE-2026-106205)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Passwords in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


139) Race condition (CVE-ID: CVE-2026-106213)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in WebAudio in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


140) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106230)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in Offline in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


141) Missing Authorization (CVE-ID: CVE-2026-106367)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


142) Input validation error (CVE-ID: CVE-2026-106226)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Compositing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


143) Spoofing attack (CVE-ID: CVE-2026-106229)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to present misleading user interface information.

The vulnerability exists due to user interface misrepresentation in FileSystem when displaying information. A remote attacker can exploit this misrepresentation to present misleading user interface information.


144) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106232)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


145) Incorrect authorization (CVE-ID: CVE-2026-106391)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in WebShare in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


146) Observable discrepancy (CVE-ID: CVE-2026-106336)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable discrepency in Paint in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


147) Incorrect authorization (CVE-ID: CVE-2026-106403)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Accessibility in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


148) Use-after-free (CVE-ID: CVE-2026-106373)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Fonts in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


149) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106301)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in Contextual Tasks in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


150) Buffer overflow (CVE-ID: CVE-2026-106292)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to boundary error in Fonts in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a buffer overflow and crash the browser.


151) Incomplete cleanup (CVE-ID: CVE-2026-106262)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in GetUserMedia in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


152) Information disclosure (CVE-ID: CVE-2026-106360)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Payments in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


153) Incomplete cleanup (CVE-ID: CVE-2026-106375)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Dawn in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


154) Information disclosure (CVE-ID: CVE-2026-106348)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Animation in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


155) Incorrect authorization (CVE-ID: CVE-2026-106307)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


156) Incorrect authorization (CVE-ID: CVE-2026-106212)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Autofill in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


157) Incorrect authorization (CVE-ID: CVE-2026-106398)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Media in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


158) Missing Authorization (CVE-ID: CVE-2026-106388)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in DataTransfer in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


159) Missing Authorization (CVE-ID: CVE-2026-106271)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Workers in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


160) Use of uninitialized resource (CVE-ID: CVE-2026-106395)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in Dawn in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


161) Out-of-bounds read (CVE-ID: CVE-2026-106304)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the ANGLE component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and gain access to sensitive information.


162) Out-of-bounds write (CVE-ID: CVE-2026-106401)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in Media. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


163) Information disclosure (CVE-ID: CVE-2026-106330)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Paint in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


164) Incorrect authorization (CVE-ID: CVE-2026-106295)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Unbounded Element in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


165) Incorrect authorization (CVE-ID: CVE-2026-106352)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in WebProtect in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


166) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106337)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


167) Input validation error (CVE-ID: CVE-2026-106263)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in SignIn in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


168) Incorrect authorization (CVE-ID: CVE-2026-106404)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in FontAccess in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


169) Missing Authorization (CVE-ID: CVE-2026-106183)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Chromoting in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


170) Use of uninitialized resource (CVE-ID: CVE-2026-106386)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in WebAudio in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


171) Observable discrepancy (CVE-ID: CVE-2026-106351)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable discrepency in Safebrowsing in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


172) Missing Authorization (CVE-ID: CVE-2026-106384)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to missing authorization in SiteIsolation when enforcing site isolation restrictions. A remote attacker can perform operations without the required authorization to bypass authorization restrictions.


173) Race condition (CVE-ID: CVE-2026-106207)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in V8 in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


174) Information disclosure (CVE-ID: CVE-2026-106321)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Editing in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


175) Observable discrepancy (CVE-ID: CVE-2026-106210)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable discrepency in Scroll in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


176) Information disclosure (CVE-ID: CVE-2026-106254)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Mobile in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and gain access to sensitive information.


177) Incorrect authorization (CVE-ID: CVE-2026-106372)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


178) Type Confusion (CVE-ID: CVE-2026-106341)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and gain access to sensitive information.


179) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106409)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in WebAppInstalls in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


180) Missing Authorization (CVE-ID: CVE-2026-106340)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in CredentialProvider in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


181) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106276)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Payments in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


182) Spoofing attack (CVE-ID: CVE-2026-106338)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misrepresent the user interface.

The vulnerability exists due to user interface misrepresentation in the PictureInPicture feature when displaying picture-in-picture content. A remote attacker can exploit misleading interface presentation to misrepresent the user interface.


183) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106317)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in FullScreen in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


184) Missing Authorization (CVE-ID: CVE-2026-106344)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to missing authorization in the Permissions component when handling permission-related operations. A remote attacker can perform operations without the required authorization to bypass authorization checks.


185) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106359)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in DeviceBoundSessionCredentials in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


186) Input validation error (CVE-ID: CVE-2026-106353)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


187) Missing Authorization (CVE-ID: CVE-2026-106312)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access to sign-in functionality.

The vulnerability exists due to missing authorization in the SignIn component when handling sign-in operations. A remote attacker can invoke sign-in operations without authorization to gain unauthorized access to sign-in functionality.


188) Missing Authorization (CVE-ID: CVE-2026-106191)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Actor in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


189) Missing Authorization (CVE-ID: CVE-2026-106250)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Actor in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


190) Incorrect authorization (CVE-ID: CVE-2026-106309)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Selection in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


191) Missing Authorization (CVE-ID: CVE-2026-106187)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Permissions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


192) Incomplete cleanup (CVE-ID: CVE-2026-106394)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Glic in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


193) Incorrect authorization (CVE-ID: CVE-2026-106306)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


194) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106427)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


195) Incorrect comparison (CVE-ID: CVE-2026-106252)

CWE-ID: CWE-697 - Incorrect Comparison

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incorrect comparision in Fonts in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


196) Information disclosure (CVE-ID: CVE-2026-106287)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an information disclosure weakness in CORS when handling cross-origin resource sharing. A remote attacker can exploit the CORS weakness to disclose information.


197) Incorrect authorization (CVE-ID: CVE-2026-106297)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Scheduling in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


198) Incorrect authorization (CVE-ID: CVE-2026-106260)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


199) Missing Authorization (CVE-ID: CVE-2026-106362)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in DevTools in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


200) Use of uninitialized resource (CVE-ID: CVE-2026-106275)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to use of an uninitialized resource in GPU in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


201) Incorrect authorization (CVE-ID: CVE-2026-106199)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Actor in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


202) Input validation error (CVE-ID: CVE-2026-106299)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in WebAudio in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


203) Incorrect authorization (CVE-ID: CVE-2026-106422)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in API in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


204) Untrusted search path (CVE-ID: CVE-2026-106186)

CWE-ID: CWE-426 - Untrusted Search Path

CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to uncontrolled search path element in CredentialProvider in Google Chrome. A local user can place a specially crafted file into a certain location on the system and potentially escalate privileges.


205) Buffer overflow (CVE-ID: CVE-2026-106247)

CWE-ID: CWE-120 - Buffer overflow

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to boundary error in ANGLE in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger a buffer overflow and crash the browser.


206) Information disclosure (CVE-ID: CVE-2026-106192)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to information exposure in the mobile component when using mobile browser functionality. A remote attacker can access exposed information to disclose information.


207) Out-of-bounds read (CVE-ID: CVE-2026-106399)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary condition within the Skia component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger an out-of-bounds read error and crash the browser.


208) Missing Authorization (CVE-ID: CVE-2026-106264)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Web Authentication (Passkeys & Security Keys) in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


209) Spoofing attack (CVE-ID: CVE-2026-106285)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof user interface information.

The vulnerability exists due to user interface misrepresentation in WebAppInstalls when presenting interface information. A remote attacker can exploit the interface misrepresentation to spoof user interface information.


210) Information disclosure (CVE-ID: CVE-2026-106220)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information leakage in the Passwords feature when handling password information. A remote attacker can exploit the information leak to disclose sensitive information.


211) Integer overflow (CVE-ID: CVE-2026-106417)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to crash the browser.

The vulnerability exists due to a integer overflow in Media in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


212) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-106221)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to unintended forwarding of requests to an external entity in WebAPKs in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


213) Incorrect authorization (CVE-ID: CVE-2026-106259)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in PermissionElement when evaluating permissions. A remote attacker can exploit incorrect authorization checks to bypass authorization restrictions.


214) Improper privilege management (CVE-ID: CVE-2026-106296)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper privilege management in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


215) Incorrect authorization (CVE-ID: CVE-2026-106249)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Autofill in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


216) Type Confusion (CVE-ID: CVE-2026-106374)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a type confusion error within the V8 component in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a type confusion error and crash the browser.


217) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106380)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


218) Spoofing attack (CVE-ID: CVE-2026-106179)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof the user interface.

The vulnerability exists due to user interface misrepresentation in WebAppInstalls when presenting its user interface. A remote attacker can exploit misleading interface presentation to spoof the user interface.


219) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106368)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


220) Information disclosure (CVE-ID: CVE-2026-106237)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to unintended information exposure in the Permissions component when permissions are handled. A remote attacker can trigger the information leak to disclose sensitive information.


221) Input validation error (CVE-ID: CVE-2026-106331)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to insufficient validation of user-supplied input in Extensions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


222) Incorrect authorization (CVE-ID: CVE-2026-106270)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in WebAppInstalls in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


223) Incorrect authorization (CVE-ID: CVE-2026-106350)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


224) Missing Authorization (CVE-ID: CVE-2026-106288)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Browser in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


225) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106305)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Mobile in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


226) Missing Authorization (CVE-ID: CVE-2026-106418)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


227) State Issues (CVE-ID: CVE-2026-106343)

CWE-ID: CWE-371 - State Issues

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper state validation in Autofill AI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


228) Incorrect authorization (CVE-ID: CVE-2026-106371)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Transactions Platform in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


229) Information disclosure (CVE-ID: CVE-2026-106256)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information exposure in the Passwords component when the information leak is triggered. A remote attacker can exploit the information leak to disclose sensitive information.


230) Race condition (CVE-ID: CVE-2026-106413)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Browser in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


231) Improper resource shutdown or release (CVE-ID: CVE-2026-106339)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper resource release in Core in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


232) Improper resource shutdown or release (CVE-ID: CVE-2026-106320)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper resource release in UI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


233) Incorrect authorization (CVE-ID: CVE-2026-106195)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due incorrect authorization checks in Chromoting in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


234) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106316)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Chromoting in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


235) Race condition (CVE-ID: CVE-2026-106385)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a race condition in in Chromoting in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page and crash the browser.


236) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-106325)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to use of incorrectly resolved reference in Core in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


237) Incorrect provision of specified functionality (CVE-ID: CVE-2026-106390)

CWE-ID: CWE-684 - Incorrect Provision of Specified Functionality

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of certain functionality in SanitizerAPI in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass security restrictions.


238) Incomplete cleanup (CVE-ID: CVE-2026-106294)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to incomplete cleanup in Chromoting in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage and crash the browser.


239) Information disclosure (CVE-ID: CVE-2026-106334)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to information disclosure in Payments in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


240) Spoofing attack (CVE-ID: CVE-2026-106236)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof user interface information.

The vulnerability exists due to user interface misrepresentation in Chromoting when displaying interface information. A remote attacker can exploit misleading interface presentation to spoof user interface information.


241) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106251)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Chromoting in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


242) Improper resource shutdown or release (CVE-ID: CVE-2026-106310)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper resource release in FontAccess in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


243) Improper resource shutdown or release (CVE-ID: CVE-2026-106345)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to improper resource release in Session in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


244) Multiple Interpretations of UI Input (CVE-ID: CVE-2026-106272)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to multiple interpretation of UI input in Chromoting in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and perform a spoofing attack.


245) Missing Authorization (CVE-ID: CVE-2026-106355)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to missing authorization checks in Media in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.


246) Use-after-free (CVE-ID: CVE-2026-106234)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in Network in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


247) Use-after-free (CVE-ID: CVE-2026-106269)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to use-after-free error in CSS in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and crash the browser.


Remediation

Install update from vendor's website.

References